License & Deployment Mix: 10 tools – 4 OSS (2 traditional + 2 AiTM), 1 niche, 5 commercial.
Color: Purple team (red operators run the campaign; blue measures the result).
What Is This Category?
Phishing simulation is the send-the-phish part of the security-awareness loop. A platform ships realistic-looking phishing emails to a chosen user list, tracks click-through / submission / report rates, and (for sophisticated workflows) hands the failing user to an inline training module. Distinct from security-awareness training which is the e-learning catalogue itself.
The category splits between OSS phishing frameworks (for technical / red-team engagements; GoPhish / King Phisher / Evilginx 2 / Modlishka) and commercial awareness platforms that bundle phishing simulation with training, reported-email triage, and just-in-time micro-learning (KnowBe4 / Cofense / Hoxhunt / SoSafe; Microsoft Attack Simulation Training for M365-aligned customers).
Distinct from neighbouring categories
- Security Awareness Training – Awareness training is the e-learning catalogue; this category is the live phishing- campaign infrastructure. Commercial vendors (KnowBe4 etc.) bundle both, but the two capabilities are distinct.
- Email Security – Email security blocks real phish at the perimeter; phishing simulation sends fake phish that passes the perimeter for training measurement
- Breach & Attack Simulation (BAS) – BAS validates whole detection chains; phishing simulation is specifically the human-factor test
The information on these pages was researched by a combination of human review and large language models. To suggest an addition or correction, please contact us. Prepared by Rhodium Systems Inc., author of the ResorsIT platform — a unified IT operations management platform for IT teams and MSPs that integrates a curated suite of open-source, commercial, and SaaS applications into a single system with shared identity, single sign-on, access control, and a common audit trail. Use this catalogue only as a starting point for your own research, and review any tool carefully against your own requirements before relying on it. Catalogue data version 2026.197.
Comparison
Category Overview
Phishing simulation splits along two axes: OSS phishing frameworks for technical / red-team engagements (GoPhish, King Phisher for traditional credential phishing; Evilginx 2 and Modlishka for adversary-in-the-middle MFA-bypass scenarios) and commercial awareness platforms that bundle phishing simulation with training, reported-email triage, and just-in-time micro-learning (KnowBe4, Cofense, Hoxhunt, SoSafe; Microsoft Attack Simulation Training for M365-aligned customers).
Note that the awareness training content side is covered in Security Awareness Training; this category covers the phishing-simulation infrastructure specifically.
Operational Model
What each tool is for.
| Tool | Traditional Phish | AiTM | Awareness Training | Just-in-Time | Reported-Email |
|---|---|---|---|---|---|
| GoPhish | yes | – | – | – | – |
| King Phisher | yes | partial | – | – | – |
| Evilginx 2 | – | yes (first-class) | – | – | – |
| Modlishka | – | yes | – | – | – |
| Caido AiTM Plugin | – | partial | – | – | – |
| KnowBe4 | yes | partial | yes (KMSAT) | yes | yes (PhishER) |
| Cofense | yes | partial | yes | yes | yes (Triage) |
| Hoxhunt | yes (AI-personalised) | – | yes | yes | yes |
| SoSafe | yes | – | yes | yes | yes |
| Microsoft Attack Sim | yes | – | yes | yes | yes (Defender) |
License Comparison
| Tool | License | OSI | Type |
|---|---|---|---|
| GoPhish | MIT | yes | OSS framework |
| King Phisher | BSD-3-Clause | yes | OSS framework |
| Evilginx 2 | BSD-3-Clause | yes | OSS AiTM framework (CE) |
| Modlishka | MIT | yes | OSS AiTM framework |
| Caido AiTM Plugin | Proprietary (mixed) | – | Caido + community plugin |
| KnowBe4 | Proprietary | – | Commercial SaaS (category leader) |
| Cofense | Proprietary | – | Commercial SaaS |
| Hoxhunt | Proprietary | – | Commercial SaaS (European) |
| SoSafe | Proprietary | – | Commercial SaaS (German) |
| Microsoft Attack Sim | Proprietary | – | M365 E5 (included) |
SSO / OIDC
| Tool | OIDC | SAML | SCIM | Notes |
|---|---|---|---|---|
| GoPhish | plugin | none | none | Reverse-proxy auth |
| King Phisher | plugin | none | none | Reverse-proxy auth |
| Evilginx 2 | n/a | n/a | n/a | Headless reverse proxy |
| Modlishka | n/a | n/a | n/a | Headless reverse proxy |
| Caido AiTM Plugin | n/a | n/a | n/a | Plugin in operator’s Caido app |
| KnowBe4 | paid | paid | paid | Enterprise tier |
| Cofense | paid | paid | paid | Enterprise tier |
| Hoxhunt | paid | paid | paid | Enterprise tier |
| SoSafe | paid | paid | paid | Enterprise tier |
| Microsoft Attack Sim | native | native | native | Entra-native (E5) |
Deployment Comparison
| Tool | Deployment | Resources | Notes |
|---|---|---|---|
| GoPhish | Single Go binary / Docker | Modest | Self-hosted |
| King Phisher | Python server + GTK client | Modest | Self-hosted |
| Evilginx 2 | Single Go binary on public VPS | Modest + public domain | Self-hosted; needs reachable VPS |
| Modlishka | Single Go binary on public VPS | Modest + public domain | Self-hosted |
| Caido AiTM Plugin | Caido desktop app + plugin | Workstation | Per-operator |
| KnowBe4 | SaaS | – | Vendor-managed |
| Cofense | SaaS | – | Vendor-managed |
| Hoxhunt | SaaS | – | Vendor-managed |
| SoSafe | SaaS | – | Vendor-managed |
| Microsoft Attack Sim | SaaS | – | Microsoft 365 native |
Composition Patterns
1. OSS-only pentest practice
GoPhish (or King Phisher) -- traditional credential phishing campaigns Evilginx 2 (or Modlishka) -- AiTM MFA-bypass scenarios
Output: full pentest phishing toolkit at zero license cost. Use during authorised engagements only.
2. Commercial managed awareness + simulation
KnowBe4 (or Cofense, Hoxhunt, SoSafe)
Output: combined awareness + simulation + reported- email triage in one platform. Replaces the Security Awareness Training training tier plus this category in one purchase.
3. Microsoft-aligned customer
Microsoft Attack Simulation Training (E5 included)
Output: lowest-friction option for M365-aligned customers. Less feature-rich than dedicated platforms but zero additional cost.
4. Managed hybrid
Hoxhunt or SoSafe -- customer-facing awareness + sim GoPhish + Evilginx 2 -- on-demand red-team / pentest phishing
Output: separation between always-on user-facing training (commercial) and on-demand technical engagement work (OSS).
Cost Tier
Per-user annual TCO.
| Tier | Tooling | Approx Cost |
|---|---|---|
| Free | GoPhish / King Phisher / Evilginx / Modlishka | $0 + operator time + VPS hosting |
| M365 included | Attack Simulation Training | (included in E5) |
| Mid | KnowBe4 / Cofense / Hoxhunt / SoSafe | $20-60 per user / year |
Tools
10 tools.
Caido AiTM Plugin
Community AiTM plugin for the Caido web proxy; lightweight alternative to Evilginx / Modlishka for adversary-in-the-middle scenarios; niche.
License: LicenseRef-caido-mixed (source-available) · Kind: cli · Deploy: native · SSO: none
Cofense PhishMe
Commercial phishing simulation + Triage reported-email platform; deep IR heritage; second-largest after KnowBe4.
License: Proprietary (proprietary) · Kind: web · Deploy: saas · SSO: OIDC, SAML
Evilginx 2
Open-source reverse-proxy phishing framework for adversary-in-the- middle credential and session-cookie capture; bypasses many MFA controls.
License: BSD-3-Clause (OSS) · Kind: service · Deploy: native, docker · SSO: none
GoPhish
Open-source phishing simulation framework written in Go; single- binary deployment, REST API, the default OSS choice for self-hosted phishing programmes.
License: MIT (OSS) · Kind: web · Deploy: native, docker · SSO: OIDC
Hoxhunt
Newer Finnish commercial phishing-sim platform; AI-personalised phishing + training; gamified user experience.
License: Proprietary (proprietary) · Kind: web · Deploy: saas · SSO: OIDC, SAML
King Phisher
Open-source phishing campaign toolkit; Python-based client-server architecture; actively maintained alternative to GoPhish.
License: BSD-3-Clause (OSS) · Kind: web · Deploy: native, docker · SSO: OIDC
KnowBe4 PhishER / KMSAT
Category-leading commercial phishing simulation + awareness training platform; Stu Sjouwerman-founded; massive customer base.
License: Proprietary (proprietary) · Kind: web · Deploy: saas · SSO: OIDC, SAML
Microsoft Attack Simulation Training
Microsoft Defender for Office 365 phishing simulation tier; included in E5 licensing; the M365-native option.
License: Proprietary (proprietary) · Kind: web · Deploy: saas · SSO: OIDC, SAML
Modlishka
Open-source AiTM phishing reverse-proxy from Piotr Duszynski; predates Evilginx 2; Go-based; popular in red-team training.
License: MIT (OSS) · Kind: service · Deploy: native, docker · SSO: none
SoSafe
German commercial phishing-sim + awareness platform; rapid growth in EU; behavioural-psychology-driven design.
License: Proprietary (proprietary) · Kind: web · Deploy: saas · SSO: OIDC, SAML